{"_id":"@aviato-media/pilot-client-sdk","_rev":"12-ff3f327af2071ac5c3541f1e9d287618","name":"@aviato-media/pilot-client-sdk","dist-tags":{"latest":"1.9.0"},"versions":{"1.0.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.0.0","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.0.0","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"cf13a4ec37cd9ff24bac232301d3318732d50cf1","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.0.0.tgz","fileCount":38,"integrity":"sha512-013WWFGudgY0ZWURJtup8U0gyqHhAWH7PTNJvgNgtjI0WW7ZPcd4Yq0fZghD2Ot9d1NTUCeqylztW4W0FPjytw==","signatures":[{"sig":"MEUCICLfuc2HV+0GY/sC2T7y5AW73n900oEgN2415zSzHcPCAiEA7nakicP2v5AE2a0wbcRDkKM+3e6u1NujwR7oWpxuE9I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"cf13a4ec37cd9ff24bac232301d3318732d50cf1","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-013WWFGudgY0ZWURJtup8U0gyqHhAWH7PTNJvgNgtjI0WW7ZPcd4Yq0fZghD2Ot9d1NTUCeqylztW4W0FPjytw==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"0.1.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.0.0_1779220261817_0.8497473487777212","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@aviato-media/pilot-client-sdk","version":"1.0.1","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.0.1","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"21362f65ba16c32698bd5a51011916b7d407c369","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.0.1.tgz","fileCount":38,"integrity":"sha512-wxjLAD0yAt/DsNFtJ77n0GgUCMKea5EQu62xsOznued+gW2n//TeQRqUnBTtO/XeECnIY9/cReNGUQCm5Ltf4Q==","signatures":[{"sig":"MEQCIF4tgusZ9OyTDsAdLflrV+39y2CSbQNF6aTGajWr+n0iAiAprEye9Q08R7rBtRW6T2Qn5uTK5bB506YOliaH711+tg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"21362f65ba16c32698bd5a51011916b7d407c369","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-wxjLAD0yAt/DsNFtJ77n0GgUCMKea5EQu62xsOznued+gW2n//TeQRqUnBTtO/XeECnIY9/cReNGUQCm5Ltf4Q==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.0.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.0.1_1779221421934_0.7535717786608871","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@aviato-media/pilot-client-sdk","version":"1.1.2","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.1.2","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"b56db3096501f45baec8a88a350bd79074c16f60","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.1.2.tgz","fileCount":38,"integrity":"sha512-5pGFNb7uRwiqGBBth8EsgAcRz3zWtnSLcOdMmSwcXBOHTEU9YZBY6eHiuBflp5uID5y6BOCHPBVHBBtIecCE6w==","signatures":[{"sig":"MEUCIBchEOgivozMXM3WYz51FN8ArvY0pbyLDCrRzUnNWTYQAiEA+vO+FMtW0Zpqs2x6BrqPRVXbgic+kp8+v7yyOOW3CdU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"b56db3096501f45baec8a88a350bd79074c16f60","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-5pGFNb7uRwiqGBBth8EsgAcRz3zWtnSLcOdMmSwcXBOHTEU9YZBY6eHiuBflp5uID5y6BOCHPBVHBBtIecCE6w==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.1.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.1.2_1779244715372_0.6890235394416346","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.2.0","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.2.0","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"e735b279e86b0ed65eb156db056eb043fcc28e4c","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.2.0.tgz","fileCount":38,"integrity":"sha512-yDkTBPMqlP30WY23Y/vauAiVqwzhjJjCWYRb0XyQcqz7+wTW1bc6+iQ6VwDmeQa4Gge98Ho4NXuAJhj3opwvHw==","signatures":[{"sig":"MEQCIBWuq0uOsIIZecR7JqsK48OERjw3vgLDJo3tKFplM4PIAiB9TyVtxzuN/nZ3K3AsGURPiW7DRxK/wdTT0ECTXZu6dg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"e735b279e86b0ed65eb156db056eb043fcc28e4c","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-yDkTBPMqlP30WY23Y/vauAiVqwzhjJjCWYRb0XyQcqz7+wTW1bc6+iQ6VwDmeQa4Gge98Ho4NXuAJhj3opwvHw==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.2.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.2.0_1779279114768_0.7921939343341897","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.3.0","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.3.0","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"b0d227c571641708b40b5f35fb7a846996cc8943","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.3.0.tgz","fileCount":38,"integrity":"sha512-cquAB8GlpyLKkEBAyyIQsrjhxZhio+UVWCXj+cvOGSifBDj0eWLH078I1VUgeePnG8V+7hKiqbFfkjWJYratIg==","signatures":[{"sig":"MEQCIBH6EIAMM8h/HD/oGPWu017yEGVPL8EjR5ndjgYD9I7JAiBVlNSQ8lmVdpFNub1kWeKUrF6qFfVF4qip9yazN260+g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"b0d227c571641708b40b5f35fb7a846996cc8943","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-cquAB8GlpyLKkEBAyyIQsrjhxZhio+UVWCXj+cvOGSifBDj0eWLH078I1VUgeePnG8V+7hKiqbFfkjWJYratIg==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.3.0_1779280632328_0.8087429399959969","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.4.0","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.4.0","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"1d30d9109d39ef915f2de309c7e19bd8a4d17801","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.4.0.tgz","fileCount":38,"integrity":"sha512-obiJTaNNqv9HP/FOFda73KWc5p1i6BlZ+7yC0oHM3PJHkgqN0hZ37dTqwzddoDTYaDRUIXv/Z0Sd7nTeC59f7g==","signatures":[{"sig":"MEQCID+iBfa5ZUOttJsEE6Jn+2jp8e56gDzRL5v/oWmimvwkAiA5EpDLrToBYZOOra5KndzeOQhU57BboWNRnMm75Ue2YQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"1d30d9109d39ef915f2de309c7e19bd8a4d17801","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-obiJTaNNqv9HP/FOFda73KWc5p1i6BlZ+7yC0oHM3PJHkgqN0hZ37dTqwzddoDTYaDRUIXv/Z0Sd7nTeC59f7g==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.4.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.4.0_1779283102372_0.6587274046189155","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.5.0","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.5.0","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"877c68a6e3363060489007db72b730218cbc2792","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.5.0.tgz","fileCount":38,"integrity":"sha512-+Ty2508B1rmUTmp98K3R6rhuzFLo7nW4Of1nMwPIWMPmcfxtpARVHUjKN4OLvrhanYoLG6YdDu1KpQcebJ2HOw==","signatures":[{"sig":"MEYCIQCl5qT4R3OpCcXieWeqLMlvv85ioxXZLB6BnW3EvMK2pgIhAKMG5+rLtuGUzjZ91vdrnJGW01bOBvHS4rYzCPFMm7mh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"877c68a6e3363060489007db72b730218cbc2792","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-+Ty2508B1rmUTmp98K3R6rhuzFLo7nW4Of1nMwPIWMPmcfxtpARVHUjKN4OLvrhanYoLG6YdDu1KpQcebJ2HOw==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.5.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.5.0_1779283725248_0.9719449106725992","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.6.0","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.6.0","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"3ee7120bbe7f7fa12630ceb73883c5dcb3decaab","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.6.0.tgz","fileCount":38,"integrity":"sha512-JSfrZDSGqJUi8joBNoHKAy1RDCkoWU78ctWxJiDwcdxWRbIzjD0ycjQLWX+f1NCI2uzz9G1wBlwrkFRX8NgkPQ==","signatures":[{"sig":"MEUCIDcyrVTDP3FisRW7Wff6I22gIMTs0tzN04+YO8nJEcaaAiEA4Wd9hfn571hb61bdHDHpJlU/x0LM0eNg/8bA21MWtYo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"3ee7120bbe7f7fa12630ceb73883c5dcb3decaab","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-JSfrZDSGqJUi8joBNoHKAy1RDCkoWU78ctWxJiDwcdxWRbIzjD0ycjQLWX+f1NCI2uzz9G1wBlwrkFRX8NgkPQ==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.6.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.6.0_1779284058892_0.5980992869928803","host":"s3://npm-registry-packages-npm-production"}},"1.6.1":{"name":"@aviato-media/pilot-client-sdk","version":"1.6.1","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.6.1","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"5a21ba3d1789e7f5d32db0aacd0ec8fc81bef9ed","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.6.1.tgz","fileCount":38,"integrity":"sha512-es9UCrhbd29rXc92OxVWIHw+T6Zvp0i5KR3BaS5ZzdU4zY1/Adz7C/gPoRGafbO1jE5BbJz11D/1mAg9hJCyBA==","signatures":[{"sig":"MEQCIBgyy+IOJuvoRdYMZ3fQvtK8RNNJrVYy40N0I0rujmz3AiA8zFJoHnkHJ9zkFfkocMaGBkQggKZtou2s7K5QjBRkPg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"5a21ba3d1789e7f5d32db0aacd0ec8fc81bef9ed","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-es9UCrhbd29rXc92OxVWIHw+T6Zvp0i5KR3BaS5ZzdU4zY1/Adz7C/gPoRGafbO1jE5BbJz11D/1mAg9hJCyBA==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.6.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.6.1_1779286329967_0.9045487497412454","host":"s3://npm-registry-packages-npm-production"}},"1.7.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.7.0","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.7.0","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"0c3b9a6982997939ac7ec757cccd87bb3bfba23a","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.7.0.tgz","fileCount":38,"integrity":"sha512-8zwMZy0Sv7XjUBy81E7m4us5pZfCbcrbsrMzpBFyx+w66TL1YHUf0MtYnaNiqhNQGKb0wop8SaP2tYtqhRwOyA==","signatures":[{"sig":"MEUCIQCsfWiuh6XBEh/bVbEhkimQ9bE0cI/SoJKfXUQGFZY4AwIgZuriEOA+WqVsxExpjfe4nV5NoKm1vcrQDKNXVL9XjcI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"0c3b9a6982997939ac7ec757cccd87bb3bfba23a","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-8zwMZy0Sv7XjUBy81E7m4us5pZfCbcrbsrMzpBFyx+w66TL1YHUf0MtYnaNiqhNQGKb0wop8SaP2tYtqhRwOyA==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.7.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.7.0_1779332020958_0.07512301180963954","host":"s3://npm-registry-packages-npm-production"}},"1.8.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.8.0","license":"MIT","_id":"@aviato-media/pilot-client-sdk@1.8.0","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"dist":{"shasum":"2965537373000b118c3f9aaedda25a4f0f962b08","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.8.0.tgz","fileCount":38,"integrity":"sha512-R3EUN0KuzMvZW+c42SLB+oB/naHATuUcvvdTUuShv3P1VCp84yaJEG1Hd8BtLxVvrxKaFh0W4TAOK6igaOdDSw==","signatures":[{"sig":"MEQCIGZvK7yNYUIj0EWafudmGXzLUGKTCotZ8d7PtlimrvatAiA+mXRqQLrvoUtoiQNv/6DZaT4ynJEecmi7sEF+gu+W5g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113768},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","shasum":"2965537373000b118c3f9aaedda25a4f0f962b08","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch","test":"bun test __tests__/","build":"rm -rf dist && tsc -p tsconfig.build.json","clean":"rm -rf dist .turbo","prepack":"bun run build","coverage":"bun test --coverage __tests__/","typecheck":"tsc --noEmit"},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"_integrity":"sha512-R3EUN0KuzMvZW+c42SLB+oB/naHATuUcvvdTUuShv3P1VCp84yaJEG1Hd8BtLxVvrxKaFh0W4TAOK6igaOdDSw==","repository":{"url":"git+https://github.com/aviato-media/pilot-sdk.git","type":"git","directory":"packages/client-sdk"},"_npmVersion":"10.8.3","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"4.4.3","@aviato-media/pilot-core":"1.8.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/pilot-client-sdk_1.8.0_1779373167391_0.1316752099178875","host":"s3://npm-registry-packages-npm-production"}},"1.9.0":{"name":"@aviato-media/pilot-client-sdk","version":"1.9.0","description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","license":"MIT","repository":{"type":"git","url":"git+https://github.com/aviato-media/pilot-sdk.git","directory":"packages/client-sdk"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"build":"rm -rf dist && tsc -p tsconfig.build.json","dev":"tsc -p tsconfig.build.json --watch","typecheck":"tsc --noEmit","test":"bun test __tests__/","coverage":"bun test --coverage __tests__/","clean":"rm -rf dist .turbo","prepack":"bun run build"},"dependencies":{"@aviato-media/pilot-core":"1.9.0","zod":"4.4.3"},"// @bun-upgrade":"","devDependencies":{"bun-types":"^1.3.14","typescript":"^5.9.3"},"_id":"@aviato-media/pilot-client-sdk@1.9.0","_integrity":"sha512-61xg26DIusLksb1roDVYotpCOjlRTvKDS49HxSEBZEInv/s4s8F74vqtyDdNgX7Skvgh/lZCOQS8sDkPtOgUqw==","_nodeVersion":"24.3.0","_npmVersion":"10.8.3","shasum":"c1654f53fa2588cd61deb4f265fa4639712d7a61","dist":{"integrity":"sha512-61xg26DIusLksb1roDVYotpCOjlRTvKDS49HxSEBZEInv/s4s8F74vqtyDdNgX7Skvgh/lZCOQS8sDkPtOgUqw==","shasum":"c1654f53fa2588cd61deb4f265fa4639712d7a61","tarball":"https://registry.npmjs.org/@aviato-media/pilot-client-sdk/-/pilot-client-sdk-1.9.0.tgz","fileCount":42,"unpackedSize":136219,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIF9RN1Je4uEedDECH0xAZGZknxFf/q9PSTkRVYmi058oAiBx2gr/IdNdoZZO5Wkf0qB1Csmi+/Hc4BWMnxOL2MoMbQ=="}]},"_npmUser":{"name":"benhutchins","email":"ben@hutchins.co"},"directories":{},"maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pilot-client-sdk_1.9.0_1780078903558_0.7583228640521869"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-19T19:51:01.622Z","modified":"2026-05-29T18:21:43.870Z","1.0.0":"2026-05-19T19:51:01.946Z","1.0.1":"2026-05-19T20:10:22.115Z","1.1.2":"2026-05-20T02:38:35.513Z","1.2.0":"2026-05-20T12:11:54.919Z","1.3.0":"2026-05-20T12:37:12.507Z","1.4.0":"2026-05-20T13:18:22.503Z","1.5.0":"2026-05-20T13:28:45.388Z","1.6.0":"2026-05-20T13:34:19.030Z","1.6.1":"2026-05-20T14:12:10.151Z","1.7.0":"2026-05-21T02:53:41.090Z","1.8.0":"2026-05-21T14:19:27.536Z","1.9.0":"2026-05-29T18:21:43.760Z"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/aviato-media/pilot-sdk.git","directory":"packages/client-sdk"},"description":"Aviato Pilot's License — client-side SDK. Pair with Tower, fetch + decrypt server connection info, authenticate to media servers via per-device delegation cert. For Aviato Web, Afterburner, and third-party client apps.","maintainers":[{"name":"benhutchins","email":"ben@hutchins.co"}],"readme":"# @aviato-media/pilot-client-sdk\n\nUniversal client SDK for the Aviato Pilot License — a privacy-preserving multi-server identity protocol. This package lets a third-party app pair with a user's Aviato Tower, receive a delegation cert, and authenticate against the user's media servers using only the keys it holds locally. Aviato Tower never sees the bytes that flow between client and media server.\n\nThe SDK is framework-agnostic. React bindings live in `@aviato-media/pilot-client-react`.\n\n---\n\n## Install\n\n```sh\nnpm install @aviato-media/pilot-client-sdk @aviato-media/pilot-core\n# or\nbun add @aviato-media/pilot-client-sdk @aviato-media/pilot-core\n```\n\n`@aviato-media/pilot-core` is a peer dependency — install it alongside.\n\n---\n\n## Quickstart\n\n```ts\nimport {\n  AviatoPilotClient,\n  SubtleCryptoKeyStorageBackend,\n  isSubtleCryptoStorageSupported,\n  LocalStorageBackend,\n} from '@aviato-media/pilot-client-sdk'\n\n// 1. Pick a storage backend. Prefer the secure one when available.\nconst storage = (await isSubtleCryptoStorageSupported())\n  ? new SubtleCryptoKeyStorageBackend()\n  : new LocalStorageBackend()\n\nconst client = new AviatoPilotClient({\n  appId: 'com.example.myapp',           // registered on https://tower.aviato.media/developer/apps\n  deviceName: 'Desktop Browser',        // device name to help the user, will be kept secure in Vault\n  storage,\n  towerBaseUrl: 'https://tower.aviato.media',\n})\n\n// 2. Boot — load persisted identity if any.\nawait client.hydrate()\n\n// 3. If no identity, start a pair flow. Show the user pairingUrl + code.\nif (!(await client.hasIdentity())) {\n  const handle = await client.beginPair()\n  console.log('Show this to the user:', handle.pairingUrl, handle.code)\n  await handle.await()                  // resolves when the user approves on Tower\n}\n\n// 4. Resolve the user's linked servers and sign in to each.\nawait client.initializeAllConnections()\n\n// 5. Read state — refreshes on every status change via subscribe().\nconst conns = client.getConnections()\nfor (const c of conns) {\n  // serverPubKey is a `PublicKey` — call `.toHex()` for display, or hand\n  // it back to any SDK call as-is.\n  console.log(`${c.serverPubKey} ${c.status.state}`)\n}\n\n// 6. Per-server sign-in. `serverPubKey` accepts any `PublicKeyLike`:\n//    - a `PublicKey` instance (e.g. from another SDK call)\n//    - raw 32-byte `Uint8Array`\n//    - lowercase 64-char hex string (e.g. from config or env)\nconst conn = await client.signInToServer({\n  serverPubKey: 'aa…',\n})\nif (conn.status.state === 'online') {\n  console.log('Session token:', conn.status.sessionToken)\n}\n\n// Round-trip: hand back what you got, no encoding fiddling.\nconst sameConn = await client.signInToServer({ serverPubKey: conn.serverPubKey })\n```\n\n### Key classes (`PublicKey`, `PrivateKey`, `PublicPrivateKey`)\n\nThe SDK uses class wrappers from `@aviato-media/pilot-core` so input and output share one type:\n\n- `PublicKey` — `.toHex()` / `.toString()` / `.toRaw()` / `.toBase64Url()` / `.toJSON()` / `.equals(other)`. JSON.stringify round-trips through `toHex()`. Construct from bytes, hex string, or another `PublicKey`.\n- `PrivateKey` — `.toString()` is redacted (`'[PrivateKey]'`), `.toJSON()` throws (defends against accidental leaks). Explicit secret extraction via `.toRaw()` or `.toBase64Url()`.\n- `PublicPrivateKey` — bundles `pubKey` + `privKey`. Generators: `PublicPrivateKey.generateEd25519()` / `generateX25519()`.\n\n`PublicKeyLike = PublicKey | Uint8Array | string` is the boundary input type for any public key parameter.\n\n---\n\n## What lives where\n\n| API | Use it for |\n|---|---|\n| `AviatoPilotClient` | Default. Orchestrates pair, hydrate, sign-in, sign-out, cert renewal, subscribe. |\n| `LocalStorageBackend` | Default browser storage. Persists raw private keys in localStorage. **Vulnerable to XSS exfiltration** — see below. |\n| `SubtleCryptoKeyStorageBackend` | **Recommended for production browser apps.** Persists device private keys as non-extractable WebCrypto `CryptoKey` handles in IndexedDB. |\n| `MemoryStorageBackend` | Tests / ephemeral sessions. |\n| `serverCertAuth` | Low-level per-server cert-auth handshake. Use when you want to drive sign-in manually. |\n| `resolveServerConnInfo` | Low-level conn-info fetch + verify + decrypt. Returns `{protocol, host, port}` for a server. |\n| `TowerClient` | Raw Tower HTTP client. Power users only. |\n\n---\n\n## Storage backends — pick the right one\n\n### Default: `LocalStorageBackend`\n\nStores everything in browser `localStorage`, including base64url-encoded device private keys.\n\n**Threat model:** any XSS in your app can read the keys via `localStorage.getItem(...)` and exfiltrate them off-origin. Use only for prototypes, internal tools, or apps where you accept that risk.\n\n### Production: `SubtleCryptoKeyStorageBackend`\n\nGenerates device Ed25519 (signing) + X25519 (encryption) keypairs as **non-extractable** WebCrypto `CryptoKey` handles. Persists them in IndexedDB. Identity metadata, bundle, and session tokens still live in localStorage (those are not sensitive in the same way — they don't grant signing power).\n\n**XSS containment:** an attacker with XSS can *use* the keys within the page lifetime (sign one request, open one envelope) but cannot copy the bytes anywhere persistent or off-origin. There is no `localStorage.getItem('client-priv')` to scrape.\n\n**Browser support:** Chrome 137+, Firefox 130+, Safari 17+. Use `isSubtleCryptoStorageSupported()` to probe at startup and fall back to `LocalStorageBackend` if not available.\n\n### Custom backends\n\nImplement `IdentityStorage` to plug in native secure storage (OS keychain on iOS/macOS, EncryptedSharedPreferences on Android, libsecret on Linux, Electron `safeStorage`, etc.). The optional `generateClientKeys` / `loadClientKeys` / `clearClientKeys` methods, when present, activate the handle-based code path — the SDK then never touches raw private key bytes. The `KeyOps` type defines what those methods must return:\n\n```ts\nimport type { KeyOps } from '@aviato-media/pilot-client-sdk'\n\nclass NativeKeychainBackend implements IdentityStorage {\n  async generateClientKeys(): Promise<KeyOps> {\n    // Generate keys inside your OS keychain, return KeyOps callbacks\n    // that proxy sign + ECDH through the native bridge.\n  }\n  async loadClientKeys(): Promise<KeyOps | null> { /* ... */ }\n  async clearClientKeys(): Promise<void> { /* ... */ }\n  // ... rest of IdentityStorage methods\n}\n```\n\n---\n\n## React\n\n```tsx\nimport { PilotProvider, usePairing, usePilotConnections } from '@aviato-media/pilot-client-react'\n\nfunction App() {\n  return (\n    <PilotProvider client={client}>\n      <SignInFlow />\n    </PilotProvider>\n  )\n}\n\nfunction SignInFlow() {\n  const { phase, begin, cancel } = usePairing()\n  const connections = usePilotConnections()\n  // ...\n}\n```\n\nSee `@aviato-media/pilot-client-react` for the full hook surface.\n\n---\n\n## Error codes\n\n`ServerConnection.status` is a tagged union. When `state === 'error'`, the `code` field tells you why:\n\n| `code` | Meaning | Typical UI response |\n|---|---|---|\n| `http` | Server returned a non-OK HTTP status (other than 401) | Retry / show server-error message |\n| `shape` | Server response shape was invalid | Bug or version mismatch — log it |\n| `sig` | Server signature failed verification | Show \"server identity check failed\" — likely tampered cache |\n| `no_server_pubkey` | The serverPubKey we paired with no longer exists | Re-pair |\n| `tower_sig_invalid` | Tower returned a conn-info record whose sig didn't verify | Likely Tower-side tamper / cache poisoning |\n| `shape_invalid` | Stored data corruption | Sign out + re-pair |\n| `no_identity` | No identity persisted yet | Show pair flow |\n| `unknown` | Unhandled error | Log + show retry |\n\n`state === 'unauthorized'` (with optional `httpStatus`) means the server returned 401 — the cert is no longer trusted by the server. Prompt the user to re-pair.\n\n`state === 'stale_k'` means the per-server K is stale; the SDK will refresh K from the next in-session envelope. Show \"reconnecting\" if it persists.\n\n---\n\n## Trust model\n\nThe protocol is designed to be Tower-honest at code resolution only. Concretely:\n\n1. **At first pair**, the user's browser learns the media server's pubkey via Tower (`GET /api/identity/code/:code/resolve`). The SDK trusts Tower to honestly map the user-entered code to the right serverPubKey. Once the pair completes, the user holds the serverPubKey directly and all subsequent verifications are independent of Tower.\n2. **The cert** is signed by the user's master key (M) inside their Tower-side vault. The SDK verifies the cert at first pair and again at every renewal. The first-pair check has no pre-existing `expectedUserPubKey` (we are learning it now); the trust root is enforced by the **media server** verifying session assertions against *its* own stored userPubKey — a mismatched userPubKey will fail at sign-in.\n3. **The cert MUST be minted for this app's `appId`**. The SDK checks `cert.appId === opts.appId` at `finalizePair`. A mismatch (mistaken Tower or malicious tampering) is rejected loud.\n4. **`signInToServer` uses the serverPubKey the caller passes in**, not whatever Tower happens to return. The pairing-response signature on K and the conn-info publish signature are both verified against the caller's expected serverPubKey.\n\nIf you want stronger first-pair trust (no Tower-mediated step), generate an invite token signed by the server's private key out-of-band (QR code, signed URL) and verify it before passing the bytes to `signInToServer`. The SDK does not impose a particular out-of-band channel.\n\n---\n\n## Cert renewal\n\n```ts\nconst result = await client.renewCertIfNeeded(30)  // renew if expiring within 30 days\n// result: 'renewed' | 'not-needed' | 'unavailable' | 'failed'\n```\n\nRenewal calls `verifyClientCert(..., { expectedUserPubKey })` to pin the trust root against the userPubKey learned at first pair. Tower cannot swap to a different user via renewal.\n\n---\n\n## See also\n\n- Aviato Pilot License protocol spec — `docs/specs/` in this repo.\n- `@aviato-media/pilot-core` — the cross-system protocol contract (schemas, crypto, JCS, sealedbox).\n- `@aviato-media/pilot-client-react` — React hooks built on this SDK.\n- Security review — `docs/specs/security-review.md`.\n","readmeFilename":"README.md"}